Security Guides

Short, practical guides to help you protect your accounts and devices. Written in UK English.

How to create strong passwords

Length, uniqueness, and why a password manager makes life easier.

Passphrase vs password

When random words beat random characters, and when they do not.

Password managers explained

What they do, how to choose one, and how to get started.

Common password mistakes

Reuse, predictable patterns, sharing, and other habits to avoid.

Multi-factor authentication explained

App codes, passkeys, SMS, and why a second factor matters.

Password security glossary

Plain English definitions of entropy, hashing, phishing, and more.

PIN security guide

Which PIN patterns to avoid—birth years, dates, duplicates, and sequences—and how to choose safer ones. Use our PIN risk map to visualise common combinations.

SIM swap fraud

Protect your mobile number from SIM hijacking. Learn warning signs, how SMS codes are risky, and UK response steps.

Bank transfer scams (APP fraud)

Avoid authorised push payment fraud: stop and verify before you pay, and know what to do if you've been tricked.

Check a website is legit

UK checklist to verify a site before you pay or log in—and how to report scam sites and phishing.

Browser security

Safer browser settings: update fast, reduce extension risks, protect saved passwords and synced data.

QR code scams (quishing)

How quishing works, why car parks are targeted, and what to do if you paid or entered details.

Remote support scams

Spot tech support cold calls, avoid remote access traps, and protect accounts after a scam.

Malware and fake downloads

How malware spreads, how to reduce risk, and what to do if you suspect infection.

Public Wi‑Fi safety

Risks on public networks, what encryption helps with, VPN myths, and safer alternatives.

Secure social media accounts

2SV, unique passwords, privacy settings, and what to do if your account is hacked.

Password reuse and credential stuffing

Why reused passwords fail, how credential stuffing works, and practical defences.

Secure your password manager

Master password tips, MFA, recovery codes, and what to do if your vault is compromised.

Secure cloud storage and sharing

Safer sharing defaults, permission checks, and how to avoid accidental data disclosure.

Developers: store passwords safely

OWASP and NIST checklist: hashing vs encryption, Argon2id, salts, and rate limiting.